A Practical Risk-Based Approach to AI Use on Delivery Projects

This is a practical framework for delivery teams to decide whether and how to use AI for a specific activity on government projects. The aim is informed decisions: understand the risks and apply proportionate safeguards. It is written for a UK context, but the approach should transfer to other global contexts.

It covers eleven categories of AI use: software development, code analysis, synthetic data generation, product features, user-facing support, live service operations, user research, design, content, business analysis, and general productivity. It also covers autonomy: how much the AI is allowed to do on its own. That cuts across all eleven categories.

Why this exists

This framework came out of work on government IT projects, where teams wanting to use AI kept meeting the same obstacle: no one could say whether a particular use was allowed, because no one had assessed the risks. That caution is justified, because without an understanding of the risks "no" is the right default. But it leaves teams with no way to reach any other answer. This framework sets out how to understand, document and mitigate the risks of a specific use, so that the decision rests on evidence.

How to use this

When you want to use AI for a specific activity, work through the four-step assessment below.

If you haven't used this framework before, the Getting Started guide walks you through setting up AI governance on your project.

The four steps

Step What you do
1. Scope your use Define the activity, categorise it, record how much the AI may do on its own, and assess what code and data you will share (including its classification)
2. Check the tool Confirm the tool is on your project's register and not excluded, and collect the facts about it that the risk assessment needs
3. Assess the risks Use the heatmap to identify the risks relevant to your use, then take each one through the same loop: rate it before mitigations (inherent), choose mitigations, and re-rate what is left (residual)
4. Approve, record and do the work Get the sign-off the overall inherent level requires, save the assessment (it is your record), do the work via your checklist, and share what you learned

Ground rules that always apply

These principles apply to all AI use:

Anyone using AI on project work should understand the relevant data classifications, their data protection obligations (including when a DPIA is required), this framework, and which tools are on the register. Organisations should provide AI awareness training and consider establishing AI champions.

Alignment with UK Government guidance

This framework applies UK Government guidance as an assessment process, including the AI Playbook, ATRS, NCSC guidance, the Government Security Classifications Policy, and the ICO toolkits. It does not replace that guidance. See Reference: Alignment with UK Government Guidance for the full list and a mapping to the AI Playbook's 10 principles.

Keeping this current: AI tools and guidance change quickly. Review this framework at least every six months, and when there are significant changes in government guidance, regulation, or the risk landscape.

Contents

The assessment

Reference library

Templates

Licence

The framework is licensed under CC BY-SA 4.0. This covers all the documentation in this repository, including the assessment steps, the reference library and the templates. You may copy, adapt and reuse it, including commercially, provided you give attribution:

Based on "A Practical Risk-Based Approach to AI Use on Delivery Projects" by Made Tech Ltd, licensed under CC BY-SA 4.0.

ShareAlike: if you share an adapted version, you must license it under CC BY-SA 4.0 or a compatible licence. This applies when you distribute the adaptation. Adapting the templates into policy documents used inside your own organisation is not itself sharing.

The code that builds the site is licensed separately under the MIT Licence. The licences do not grant rights in the Made Tech name or logo, and use of the framework does not imply endorsement by Made Tech.

This framework contains public sector information licensed under the Open Government Licence v3.0.

This is not legal advice. The framework is a practical aid to assessing AI use, not a substitute for your own legal, security or data protection advice. Decisions about data protection, security classification and statutory duties remain yours.